
afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.

A Security Tool for Bug Bounty, Pentest and Red Teaming.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

The Browser Exploitation Framework Project

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

CraftCMS has an RCE vulnerability via relational conditionals in the control panel

Proof-of-concept exploit chaining CRLF injection in ComfyUI-Manager's config endpoint with an arbitrary git install to achieve unauthenticated remote…

Authenticated Craft CMS RCE PoC for CVE-2026-44011

Docker lab reproducing CVE-2026-100382: unauthenticated argument-injection RCE in MediaWiki ExternalData's #get_program_data, with PoC payloads and…

The PoC of CVE-2026-44011: Craft CMS RCE with an authenticated user.

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE,…

Malicious Register Directive Code Injection Exploit

PoC exploit and scanner for CVE-2026-89026, validating the Issabel PBXAPI authentication bypass via forged HS256 JWTs across single or listed targets.

Unauthenticated SQL injection to RCE exploit for ZoneMinder 1.29/1.30 (CVE-2016-10204, EDB-41239). Single-command SQLi to webshell to reverse shell…

Self-hosted SSRF redirect, payload, callback, and DNS workbench

Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool